1/4 [#OSINT|#SOCMINT] Been a couple of months and almost forgot about the Research/PoC i was doing around the #GuntraderUK data leak.
Here is a FB Profile from one of the members which is pretty concerning especially if this individual keeps licensed firearms.
2/4 I did find more interesting posts/photo's on his timeline. A photo of him hunting with a shotgun by the looks of it and a photo/ad of a "Walther CP99 .177 Pistol" which was being advertised for sale.
3/4 I was able to find this profile pretty quickly after enriching all the email address's and phone numbers against a facebook dataset, then collecting all the pages on facebook these people like. I then looked at any profiles which followed pages around depression/suicide.
4/4 I've managed to build a pretty interesting dataset so far which consists of the following.
1/5 [#OSINT|#WORDPRESS] For anyone who's been following my previous tweets over the last few days, I'm going to show you how its possible to identify someone who's commented on Wordpress website by leveraging Gravatar and Email Address Hashing.
2/5 if we visit the following link, and scroll down to the bottom, we can see many users have engaged with the authors post as shown in the image below.
3/5 Starting with "Erick" we want to copy the Url of his profile image and paste it in to notepad or something similar. We then want to identify the part which is the md5 hash of his email address. After "/" and before "?"
1/6 [#OSINT] Gravatar is used by more than 200m users, the email address used to create your account is also hashed to create your unique profile url; which poses a massive privacy implication if you was to be able to reverse the MD5 hash but also creates an opportunity.
2/6 If you have a large enough collection of email addresses you could start by hashing every single one and storing them in a table. The more you have the greater the chance you have of being able to take a url of any Gravatar Profile and decoding the registered email address.
3/6 If you take a look at the url below you will see an example of the founders profile url being used. After hashing over 3+ billion email address i am able to lookup that hash in my table to receive the founders email address for that profile.